<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>KagisoSec</title><description>CTF writeups, exploits &amp; solutions</description><link>https://kagisosec.com/</link><item><title>HackTheBox: Postman</title><link>https://kagisosec.com/writeups/htb-postman/</link><guid isPermaLink="true">https://kagisosec.com/writeups/htb-postman/</guid><description>An Easy Linux box: an unauthenticated Redis 4.x instance writes an SSH key into the redis user&apos;s authorized_keys for a foothold, an encrypted /opt/id_rsa.bak cracks to computer2008 to reach Matt via su, and Webmin 1.910 falls to CVE-2019-12840 command injection (running as root) for a root shell.</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><category>linux</category><category>redis</category><category>ssh-key-injection</category><category>john</category><category>webmin</category><category>cve-2019-12840</category><category>command-injection</category><category>metasploit</category><category>privilege-escalation</category></item><item><title>HackTheBox: Trick</title><link>https://kagisosec.com/writeups/htb-trick/</link><guid isPermaLink="true">https://kagisosec.com/writeups/htb-trick/</guid><description>An Easy Linux box: a DNS zone transfer leaks a preprod payroll vhost, a boolean SQL injection with the MySQL FILE privilege reads the nginx config to expose a second vhost, then a str_replace LFI bypass combined with SMTP mail-spool poisoning lands RCE as michael — and a writable fail2ban action plus a passwordless sudo restart escalates to root.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate><category>linux</category><category>dns-zone-transfer</category><category>smtp</category><category>sql-injection</category><category>sqlmap</category><category>lfi</category><category>mail-poisoning</category><category>rce</category><category>fail2ban</category><category>privilege-escalation</category></item><item><title>Critical Ops</title><link>https://kagisosec.com/writeups/critical-ops/</link><guid isPermaLink="true">https://kagisosec.com/writeups/critical-ops/</guid><description>An HTB web challenge, the app shipped its JWT signing key in the client-side bundle, so reading it from DevTools let me forge an admin token, hit a privileged endpoint and grab the flag.</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><category>web</category><category>jwt</category><category>authentication-bypass</category><category>token-forgery</category><category>source-code-review</category><category>burpsuite</category></item><item><title>HackTheBox: Fluffy</title><link>https://kagisosec.com/writeups/htb-fluffy/</link><guid isPermaLink="true">https://kagisosec.com/writeups/htb-fluffy/</guid><description>An assumed-breach Windows AD box: steal a second user&apos;s NTLM hash with CVE-2025-24071, map ACLs in BloodHound, abuse GenericAll/GenericWrite with bloodyAD + Certipy shadow credentials to reach winrm_svc, then exploit an ADCS ESC16 misconfiguration to impersonate the Administrator.</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><category>active-directory</category><category>windows</category><category>smb</category><category>cve-2025-24071</category><category>ntlm</category><category>responder</category><category>bloodhound</category><category>shadow-credentials</category><category>certipy</category><category>adcs</category><category>esc16</category><category>winrm</category></item><item><title>How I Passed HTB CWES</title><link>https://kagisosec.com/blog/cwes-experience/</link><guid isPermaLink="true">https://kagisosec.com/blog/cwes-experience/</guid><description>My road to the Hack The Box Certified Web Exploitation Specialist (CWES), a year in the CBBH path, a focused month of revision, and a 4-day, 9-flag exam.</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><category>cwes</category><category>hackthebox</category><category>certification</category><category>web</category><category>career</category></item><item><title>HackTheBox: Support</title><link>https://kagisosec.com/writeups/htb-support/</link><guid isPermaLink="true">https://kagisosec.com/writeups/htb-support/</guid><description>An Easy Windows AD box, reverse-engineering a custom .NET binary to recover LDAP credentials, looting a plaintext password from an AD info attribute, then chaining GenericAll → RBCD to impersonate Administrator for SYSTEM.</description><pubDate>Sun, 24 May 2026 00:00:00 GMT</pubDate><category>active-directory</category><category>windows</category><category>smb</category><category>ldap</category><category>dotnet</category><category>bloodhound</category><category>rbcd</category><category>kerberos</category><category>winrm</category></item><item><title>HTB Fortress: Akerva</title><link>https://kagisosec.com/writeups/akerva-fortress/</link><guid isPermaLink="true">https://kagisosec.com/writeups/akerva-fortress/</guid><description>An 8-flag HTB Fortress, leaking a backup script over SNMP, bypassing auth with HTTP verb tampering, abusing a Flask LFI to forge the Werkzeug debugger PIN for RCE, then PwnKit to root and a Vigenère-encrypted final flag.</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate><category>wordpress</category><category>snmp</category><category>http-verb-tampering</category><category>lfi</category><category>werkzeug</category><category>flask</category><category>pwnkit</category><category>vigenere</category><category>linux</category></item><item><title>HackTheBox: Helix</title><link>https://kagisosec.com/writeups/htb-helix/</link><guid isPermaLink="true">https://kagisosec.com/writeups/htb-helix/</guid><description>A Medium Linux box, abusing an exposed Apache NiFi instance for RCE through H2 SQL aliases, recovering an SSH key from a support bundle, then driving an OPC UA / ICS reactor over an SSH tunnel to open a privileged maintenance window and reach root.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><category>linux</category><category>apache-nifi</category><category>rce</category><category>h2-database</category><category>ssh</category><category>opc-ua</category><category>ics</category><category>john</category><category>tunneling</category></item><item><title>My Security+ Experience</title><link>https://kagisosec.com/blog/security-plus-experience/</link><guid isPermaLink="true">https://kagisosec.com/blog/security-plus-experience/</guid><description>How I prepared for CompTIA Security+, what challenged me, and what helped me pass on my first attempt.</description><pubDate>Sat, 21 Mar 2026 00:00:00 GMT</pubDate><category>security+</category><category>comptia</category><category>certification</category><category>career</category></item><item><title>byp4ss3d, picoMini byCMU-Africa</title><link>https://kagisosec.com/writeups/picomini-byp4ss3d/</link><guid isPermaLink="true">https://kagisosec.com/writeups/picomini-byp4ss3d/</guid><description>Bypassing a file upload filter on Apache by abusing .htaccess to execute a PHP webshell disguised as a JPEG, achieving full RCE and reading the flag.</description><pubDate>Fri, 17 Oct 2025 00:00:00 GMT</pubDate><category>web</category><category>file-upload</category><category>htaccess</category><category>apache</category><category>rce</category><category>php</category><category>burpsuite</category></item></channel></rss>